SMS Blaster Attacks: Why Rogue Base Stations Are a Growing Telecom Fraud Problem
SMS blaster attacks are an emerging fraud threat most operators cannot yet see. Rather than routing messages through the network, attackers use a rogue base station to push phishing SMS straight to nearby phones, leaving no CDR, no billing record, and no firewall event behind. Because the traffic never touches the operator's core, the controls built to catch SMS fraud have nothing to inspect.
This article explains how the attack works, how to detect it at the signaling layer, and how to protect your network and subscribers.
Published:
What Is an SMS Blaster?
An SMS blaster is a portable fake base station small enough to fit in a car trunk or a backpack. The hardware is sold openly online from around $5,000, a trivial cost for organized crime. It can be kept moving or left in place: driven through traffic in a vehicle, carried through a crowd in a backpack, or set up in one busy spot such as a subway station, mall, or event venue. Its range is limited to roughly 500 meters to 2 kilometers, so attackers pick dense, high-traffic spots where one device reaches the most phones. It exploits a gap that has existed in cellular security for decades: 4G and 5G networks require mutual authentication between device and network, but 2G does not.
The attack runs in four stages: simulation, downgrade, injection, and push-back. First, the device broadcasts a 4G signal stronger than the real network's, luring nearby phones off the legitimate tower. It then forces a downgrade to unauthenticated fake 2G radio. Once a phone connects, the blaster injects an SMS directly, impersonating a bank, delivery service, or government agency, with no SMSC involved and no billing event generated anywhere. The device then releases the phone back to its real network and moves on, often before the victim has finished reading the message.
Because the attacker never touches the operator's core, none of it reaches the operator's records. The only fingerprint an SMS blaster leaves is in radio signaling at the cell level.
Why Conventional Fraud Controls Cannot See SMS Blasters
Most MNO fraud stacks are built to inspect traffic that passes through the network: SMS firewalls, CDR-based rules, charging systems. SMS blaster messages travel over the rogue device's own radio link and reach the phone directly, so a firewall built to filter interconnect and A2P routes has nothing to filter.
Turning off 2G does not close the gap either. The exploit depends on 2G support in the handset, not in the operator's network, so retiring a carrier's 2G service leaves the attack intact as long as phones still fall back to 2G. 2G network support is even available in the latest mobile handsets. Disabling 2G on the device is not a complete answer, since blasters can also operate over 3G and reach newer handsets through cell broadcast on 4G and 5G. And the SMS firewall, the first control most operators would reach for, never engages, because the message never crosses the network it guards.
This is also why the scale of the attack is hard to measure. In the fifteen seconds to five minutes it takes to lure, the device can cycle through hundreds of targets, downgrade, message, and release a phone, and each cycle looks like ordinary cell reselection. Subscriber complaints are usually the first signal, and by then the campaign may already be over.
Recent Incidents Show This Is Not an Isolated Problem
SMS blaster activity has been recorded in dozens of countries across six continents. The cases below are some of the recent ones that ended in arrests.
Belgrade, Serbia (December 2025)
- An IMSI catcher in a moving vehicle ran a smishing campaign for payment card data, and two Chinese nationals were arrested. Read our Yettel Serbia case study for how the operator detected and resolved it.
- Per the police statement, the takedown involved the ministry of internal affair’s technical unit, national CERT, and operators working together.
Almaty, Kazakhstan (reported April 2026)
- A vehicle-borne device posed as local operators and a bank, sending up to 100,000 messages an hour, the Astana Times reported.
- It worked crowded markets and shopping malls before authorities intervened.
Vienna, Austria (May 2026)
- A Chinese national was arrested near the Eurovision venue, and a second device turned up at his home.
- An operator had flagged the blaster's radio disruption signature a month earlier, per Commsrisk.
London, United Kingdom (sentenced June 2026)
- City of London Police convicted the organizer behind a driver who circled North London sending fake HMRC texts.
- The device bypassed SMS firewalls and content filters entirely.
The pattern holds across all four: detection began with a signaling anomaly or a subscriber report, arrests came weeks or months later, and each case was closed in collaboration with law enforcement, not in an isolation effort of network setting.
The Impact on Subscribers and Operators
An SMS blaster campaign does damage on two fronts, and neither shows up in the operator's records.
| Affected Party | Impact |
| Subscribers |
Phishing texts posing as a bank, courier, or government agency harvest card details, credentials, or crypto. Financial losses. Trust erosion in mobile network services. The forced 2G connection also exposes the subscriber's IMSI and IMEI and disrupts calls and data for phones pulled onto the fake radio. |
| Operators | Complaints and churn rise as subscribers blame the carrier for scam texts and dropped calls it never carried. Forced reconnections degrade handover-success and call-drop KPIs, and every bypassed message is A2P or marketing revenue left unbilled. With no record of the attack, the operator cannot show it responded. |
How Operators Can Start Detecting SMS Blaster Activity
Detection has to move to the layer where the attack actually happens. A rogue base station cannot perfectly reproduce the parameters of a real one, so it broadcasts invalid location area codes, the 2G downgrade pattern anomalies, Signaling storm of UE detach and re-attach trends in a way that is visible if anyone is looking for it.
GSMA guidance recommends correlating anomalies across multiple layers rather than trusting any single signal, since one anomaly type alone produces too many false positives to act on. That means ingesting radio network signaling, A-Interface for 2G and 3G, Iu-CS, LTE S1, and 5G NG, rather than relying on CDRs or billing data, which never see this traffic. Subscriber complaints cannot be used as a trigger, as this is a reactive approach and MNOs cannot wait for them.
Who is looking is just as important: no single MNO team typically owns this problem. Core network holds the signaling data, RAN understands base station behavior, and fraud teams handle subscriber-facing complaints. Building the collaboration path between these functions before an attack happens, rather than during one, is what separates a fast response from a slow one.
From Manual Analysis to a Standing Detection Capability
The signaling anomalies mentioned above can run continuously as automated scenarios against live feeds instead of waiting for an analyst to notice them. This is the shift GSMA has been pushing the industry toward at forums like FASG, where Heksagon presented its own SMS blaster detection methodology at FASG #34 in February 2026. Since then, Heksagon has been an active contributor to GSMA’s SMS Blaster Briefing Paper.
Heksagon's SMS Blaster Detection and Protection module, part of the Convergent Fraud Analytics platform, ingests these signaling streams. It correlates them with AI/ML models to raise detection confidence beyond what any single signal can provide. Once an attack is confirmed, the platform can identify likely-affected subscribers, trigger proactive warning notifications, and generate E-CID-based location estimates from RSRP/RSRQ data to support law enforcement in locating the device itself.
Start Watching the Layer Where SMS Blasters Live
Protecting your network against SMS blaster attacks comes down to one shift: watching the radio signaling layer where the attack leaves a trace instead of the core traffic it never touches. The operators who catch the next SMS blaster fraud attempt will be those looking at the right data source.
To evaluate SMS blaster detection for your network, contact Heksagon.
Related Reading:
-
SMS Blaster Detection in the Field: Lessons from the Yettel Serbia Incident
This attack technique has already hit a live network. Here's how it played out and what detection actually caught.
-
What Is Telecom Fraud? A Complete Guide for MNOs
See how these SMS blaster attacks compare to the fraud types your existing controls are already built for.